Command Injection in Tenable Nessus - CVE-2022-4313
Published: March 13, 2023
Tenable Nessus
Tenable Network Security
Description
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to improper input validation in plugins distributed via the Tenable plugin feed 202212081952 or later. A remote authenticated user with Scan Policy Configuration role can modify scan variables and execute arbitrary commands on credentialed scan targets.